Improper Data Query Handling in Ash_SQLite Affects Sensitive Information Access
CVE-2026-77846
What is CVE-2026-77846?
The ash_sqlite component from the ash-project is prone to a vulnerability that permits attackers to exploit the get_path/2 function, leading to unauthorized traversal through nested JSON data structures. This flaw arises from inadequate handling of JSON paths, where specific input values such as ., [, ], or $ can misinterpret the intended traversal, allowing access to embedded fields initially meant to remain hidden. Any endpoint that permits user influence over the get_path segment could inadvertently expose sensitive or private information. This issue primarily affects ash_sqlite versions from 0.1.2-rc.0 and below 0.2.18.
Affected Version(s)
ash_sqlite 0.1.2-rc.0 < 0.2.18
ash_sqlite c12be48a5b6295593199b0e445b70a4aef81d1cd < 2138480fceb654bec1845e691517ac409d0232c3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
